Permissions, Privileges, and Access Controls in Intel High Definition Audio driver - CVE-2020-12307

 

Permissions, Privileges, and Access Controls in Intel High Definition Audio driver - CVE-2020-12307

Published: November 12, 2020 / Updated: November 16, 2020


Vulnerability identifier: #VU48420
CSH Severity: Low
CVSS v4: 5.4 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-12307
CWE-ID: CWE-264
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to escalate privileges on the system.

The vulnerability exists due to application does not properly impose security restrictions, which leads to security restrictions bypass and privilege escalation.


Affected software

Intel High Definition Audio driver
Inspiron 14 7472
Inspiron 15 7572
Latitude 7290
Latitude 7390
Latitude 7390 2-in-1
Latitude 7490

How to mitigate CVE-2020-12307

Install updates from vendor's website.

Intel High Definition Audio driver - update to 9.21.00.4561
Inspiron 14 7472 - update to 6.0.9000.1
Inspiron 15 7572 - update to 6.0.9000.1
Latitude 7290 - update to 6.0.9000.1
Latitude 7390 - update to 6.0.9000.1
Latitude 7390 2-in-1 - update to 6.0.9000.1
Latitude 7490 - update to 6.0.9000.1

External References

Related Security Bulletins